Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

During a Linux forensic investigation, you find that the /var/log/auth.log file contains log entries showing multiple 'Failed password for root' messages from a single IP address, followed by a 'Accepted password for root' entry. What is the MOST likely conclusion?

⚠ Common exam trap

EC-Council CHFI often tests the distinction between authentication log patterns and exploit-based compromise, so the trap here is assuming that any successful login after failures must be a privilege escalation, when the log entries explicitly show password-based authentication succeeded.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An attacker successfully brute-forced the root password

The sequence of multiple 'Failed password for root' entries followed by an 'Accepted password for root' entry from the same IP address is the classic signature of a successful brute-force attack against the root account. SSH authentication logs record each attempt, and a successful login after repeated failures indicates that the attacker guessed or cracked the password, not that a privilege escalation or lockout occurred.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    An attacker successfully brute-forced the root password

    Why this is correct

    Repeated 'Failed password for root' entries from one source, immediately followed by 'Accepted password for root', indicate sustained password guessing that eventually succeeded. The single IP and root-targeted pattern distinguish brute force from a legitimate login or configuration error.

  • ✗

    The root user accidentally mistyped the password multiple times

    Why it's wrong here

    Repeated failures from a single remote IP address followed by acceptance indicates deliberate password guessing, not a local user mistyping at a console. Mistyped-password patterns appear as failures from the same trusted workstation or terminal, typically without a remote source address.

  • ✗

    The system was compromised via a privilege escalation exploit

    Why it's wrong here

    Repeated failures from one IP followed by an accepted root login indicates a successful brute-force or password-guessing attack, not exploitation of a local privilege escalation flaw. Privilege escalation analysis applies when a low-privileged account gains root through a kernel or SUID vulnerability after authenticating normally.

  • ✗

    The root account has been locked out due to multiple failures

    Why it's wrong here

    The log shows an accepted password after the failures, so the account was not locked; lockout would appear as further denials or a locked-account message. Lockout analysis is the right conclusion when failures continue past the configured threshold without any subsequent successful authentication.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.